panic: Caught invalid memory access at ADDR size NUM op NUM (2)

0 views
Skip to first unread message

syzbot

unread,
Aug 25, 2026, 11:37:12 AM (3 days ago) Aug 25
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 18607adc5162 Merge remote-tracking branch 'origin/master' ..
git tree: https://github.com/blackgnezdo/openbsd-src.git syzbot-kasan
console output: https://syzkaller.appspot.com/x/log.txt?x=11e19979580000
kernel config: https://syzkaller.appspot.com/x/.config?x=85e25e37d09e1b88
dashboard link: https://syzkaller.appspot.com/bug?extid=3ee2e2997a4123379813

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/0fce39fa2774/disk-18607adc.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/a427fa3cb80f/bsd-18607adc.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/332eb77d51ba/kernel-18607adc.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3ee2e2...@syzkaller.appspotmail.com

panic: Caught invalid memory access at ffff800001eef738 size 8 op 0
Starting stack trace...
panic(ffffffff8463cea0) at panic+0x25b sys/kern/subr_prf.c:229
__asan_load8_noabort(ffff800001eef738) at
__asan_load8_noabort+0xde
pf_remove_if_empty_ruleset(ffff800001eef6e8) at pf_remove_if_empty_ruleset+0x5c sys/net/pf_ruleset.c:292
pfi_dynaddr_setup(ffff800001784ff8,0,1) at pfi_dynaddr_setup+0x837 sys/net/pf_if.c:508
pf_addr_setup(ffffffff85482b50,ffff800001784ff8,0) at pf_addr_setup+0x3a sys/net/pf_ioctl.c:948
pfioctl(24900,cd604404,ffff800001c5e000,2,ffff800045ff54f8) at pfioctl+0xe43e sys/net/pf_ioctl.c:2379
VOP_IOCTL(ffff800001dcb7f0,cd604404,ffff800001c5e000,2,ffff8000001194e0,ffff800045ff54f8) at VOP_IOCTL+0x131 sys/kern/vfs_vops.c:264
vn_ioctl(ffff800001de38c0,cd604404,ffff800001c5e000,ffff800045ff54f8) at vn_ioctl+0x18c sys/kern/vfs_vnops.c:537
sys_ioctl(ffff800045ff54f8,ffff80003bb704f0,ffff80003bb70460) at sys_ioctl+0x868 sys/kern/sys_generic.c:510
syscall(ffff80003bb704f0) at syscall+0x1089 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80003bb704f0) at syscall+0x1089 sys/arch/amd64/amd64/trap.c:791
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x4ab667fdb60, count: 246
End of stack trace.
syncing disks...


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

Greg Steuck

unread,
Aug 25, 2026, 11:45:31 AM (3 days ago) Aug 25
to syzbot, syzkaller-openbsd-bugs
#syz dup: KASAN: invalid memory access in pf_remove_if_empty_ruleset

--
You received this message because you are subscribed to the Google Groups "syzkaller-openbsd-bugs" group.
To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-openbsd...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/syzkaller-openbsd-bugs/6a8db6a6.a5a502ce.31d34.006b.GAE%40google.com.
Reply all
Reply to author
Forward
0 new messages